Description
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.
Published: 2026-06-09
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A DOM-based Cross-Site Scripting flaw exists in Adobe Experience Manager that allows an attacker to manipulate the Document Object Model and inject malicious JavaScript into a victim's browser. Because the vulnerability is triggered by crafted URLs or web content, execution requires user interaction; the attacker must prompt a victim to visit a malicious page. Once invoked, the script runs with the same privileges as the victim, enabling actions like data theft, session hijacking, or defacement. The flaw is identified as CWE-79 and is mitigated in newer releases.

Affected Systems

Adobe Experience Manager versions 6.5.24, the LTS SP1 release, and the 2026.04 build are affected. Any installation of these releases that serves user-generated or external content remains vulnerable. Users of these versions should verify their current patch level and consider upgrading to a release that addresses the issue.

Risk and Exploitability

The CVSS score of 5.4 indicates a moderate severity, while the EPSS score is not available and the issue is currently not listed in the CISA KEV catalog. Exploitation requires user interaction, so the likelihood of widespread attacks is lower than for an exploitation that does not need a victim to click a link. However, once a victim visits a crafted page, the attacker can execute code with the victim's privileges, posing a significant risk to confidentiality and integrity within the affected context.

Generated by OpenCVE AI on June 9, 2026 at 21:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Adobe Experience Manager to a version newer than 6.5.24 that incorporates the security fix.
  • Deploy a content-security policy that disallows or whitelists inline script execution to reduce the impact of XSS until a patch is applied.
  • Monitor web traffic for suspicious URLs that may target AEM sites to detect potential XSS exploitation attempts.

Generated by OpenCVE AI on June 9, 2026 at 21:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 10 Jun 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe experience Manager
CPEs cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:*
cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:-:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp1:*:*:lts:*:*:*
Vendors & Products Adobe experience Manager

Wed, 10 Jun 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe adobe Experience Manager
Vendors & Products Adobe
Adobe adobe Experience Manager

Tue, 09 Jun 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Jun 2026 17:15:00 +0000

Type Values Removed Values Added
Description Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.
Title Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Adobe Adobe Experience Manager Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-06-09T20:19:10.857Z

Reserved: 2026-05-21T15:28:38.131Z

Link: CVE-2026-48266

cve-icon Vulnrichment

Updated: 2026-06-09T20:19:07.899Z

cve-icon NVD

Status : Analyzed

Published: 2026-06-09T17:17:43.117

Modified: 2026-06-10T14:49:41.433

Link: CVE-2026-48266

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-10T00:00:10Z

Weaknesses